CVE-2026-1771
Received Received - Intake

Arbitrary File Upload in MapSVG WordPress Plugin

Vulnerability report for CVE-2026-1771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Wordfence

Description

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mapsvg mapsvg to 8.14.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MapSVG plugin for WordPress allows arbitrary file uploads due to missing file type validation in versions up to 8.14.0. An incorrect conditional check prevents proper file validation, enabling authenticated attackers with Administrator access or higher to upload malicious files that could lead to remote code execution on the server.

Detection Guidance

Check for unauthorized SVG files or unexpected file uploads in WordPress directories. Review server logs for uploads by Administrator-level users. Inspect the MapSVG plugin version; if it is 8.14.0 or lower, the vulnerability is likely present.

Impact Analysis

If you use the MapSVG plugin on your WordPress site, an attacker with admin privileges could upload harmful files to your server. This could allow them to execute arbitrary code, potentially taking control of your website or accessing sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR and HIPAA requirements for data protection and security. Organizations may face legal penalties, reputational damage, and loss of trust if exploited.

Mitigation Strategies

Update the MapSVG plugin to the latest version beyond 8.14.0. Remove any unauthorized files uploaded to the server. Restrict file upload permissions to trusted users only. Monitor for signs of compromise.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart